w3c / w3c/webcrypto

Add link the Security Guidance from CFRG

Open
#145 2 comments 0 reactions 1 assignee View on GitHub

@hhalpin is already working on this.

Since Sep 12, 2016.

editorial
Dominant language
HTML
Stars
294
Forks
78
PR merge metrics
No merged PRs in 30d

Description

Quite a while back we got a formal objection from Rich Salz (https://www.w3.org/Bugs/Public/show_bug.cgi?id=25607) over lack of guidance for developers. Since then, we made a document (https://www.ietf.org/archive/id/draft-irtf-cfrg-webcrypto-algorithms-00.txt) and got it accepted at CFRG. I'd like to add, as per previous email, a reference to the CFRG document to the spec to get over the Formal Objection. I'm working with INRIA (Karthik Bharagavan and Graham Steel) to have the document updated by end of the week to take into account any new attacks over the last year.

The sentence (from https://lists.w3.org/Archives/Public/public-webcrypto/2015Oct/0040.html) that would explain this informative note is:

"Note that the security properties of particular algorithms in this specification are liable to change. Detailed questions can be asked to the IRTF CFRG, who are maintaining a document that outlines security guidelines for algorithms and key sizes as well as reference to the wider cryptographic literature."

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.